{"id":3959,"date":"2026-04-28T13:41:25","date_gmt":"2026-04-28T13:41:25","guid":{"rendered":"https:\/\/www.hackmosphere.fr\/training-program-pentest-active-directory-entra-id\/"},"modified":"2026-08-10T08:13:14","modified_gmt":"2026-08-10T08:13:14","slug":"training-program-pentest-active-directory-entra-id","status":"publish","type":"page","link":"https:\/\/www.hackmosphere.fr\/en\/training-program-pentest-active-directory-entra-id\/","title":{"rendered":"Training Program: Pentest Active Directory &#038; Entra ID"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;section&#8221; _builder_version=&#8221;4.16&#8243; global_colors_info=&#8221;{}&#8221;][et_pb_row admin_label=&#8221;row&#8221; _builder_version=&#8221;4.16&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.27.6&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; custom_margin=&#8221;102px||||false|false&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h1>Training Program: Pentest Active Directory<\/h1>\n<p><strong>Trainer<\/strong>: Florian Ecard &#8211; Ethical hacker &#8211; <a href=\"mailto:fecard@hackmosphere.fr\">fecard@hackmosphere.fr<\/a> &#8211; 06.49.98.89.87<\/p>\n<p><strong>Target audience<\/strong>: System\/network administrators, SOC teams, CISOs, junior pentesters<\/p>\n<h1>1. Pedagogical objectives<\/h1>\n<ul>\n<li>Understand the legal and methodological framework of a security audit.<\/li>\n<li>Master the technical fundamentals of Pentest.<\/li>\n<li>Understand the architecture and risks associated with Active Directory (AD) and Entra ID.<\/li>\n<li>Identify, exploit and remediate vulnerabilities.<\/li>\n<\/ul>\n<h1>2. Module content<\/h1>\n<ul>\n<li>Fundamentals\n<ul>\n<li>Logical structure (domains, OUs, GPOs, ACLs).<\/li>\n<li>Integrated services : LDAP, DNS, Kerberos, ADCS, ADFS.<\/li>\n<li>Differences between AD On-Prem \/ Entra ID \/ Azure AD DS.<\/li>\n<\/ul>\n<\/li>\n<li>AD attack techniques\n<ul>\n<li>Recognition: BloodHound, PowerView, kerbrute, Responder&#8230;<\/li>\n<li>Exploitation: Kerberoasting, AS-REP roast, NTLM relay, GPO abuse, ACL abuse&#8230;<\/li>\n<li>Post-Exploitation: DCSync, DCShadow, Golden\/Silver tickets, Shadow Credentials&#8230;<\/li>\n<\/ul>\n<\/li>\n<li>Practical workshop\n<ul>\n<li>Setting up a vulnerable lab.<\/li>\n<li>Objectives: complete compromise, exfiltration, audit report.<\/li>\n<\/ul>\n<\/li>\n<li>Security &#038; Active Defense\n<ul>\n<li>Principle of least privilege, Tier 0\/1\/2 model.<\/li>\n<li>Hardening: SMBv1 deactivation, LDAP signing, delegation blocking.<\/li>\n<li>Detection: SIEM, ACL monitoring, regular BloodHound analysis.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h1>3. Evaluation methodology<\/h1>\n<ul>\n<li>Pre-training: QCM level + needs analysis.<\/li>\n<li>During : Flag capture challenges (CTF).<\/li>\n<li>After the course: Sending of an evaluation document to assess the level acquired.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h1>4. Duration &#038; Terms<\/h1>\n<ul>\n<li>Duration: 4 days.<\/li>\n<li>Average access time: 1 month.<\/li>\n<li>Format: Face-to-face or distance learning with dedicated lab.<\/li>\n<li>Prerequisites: Knowledge of networks and Windows\/Linux systems.<\/li>\n<li>Prices: from \u20ac4,000 excl.<\/li>\n<\/ul>\n<h1>5. Adaptation to different levels<\/h1>\n<p>The training program adapts to differences in level by alternating between theoretical input and practical workshops. At the start of the session, participants&#8217; level is informally assessed through discussion &#038; targeted questions, in order to identify specific needs. <\/p>\n<p>During hands-on sessions, the trainer provides individualized support: he circulates with participants, observing their progress at their workstations and adapting his assistance according to any difficulties encountered. Less advanced participants benefit from more gradual guidance, while those who are more autonomous can go deeper into the scenarios with complementary objectives. <\/p>\n<p>Exercises are designed with a minimum common objective, supplemented by more advanced variants. Pooling time is used to clarify important notions and consolidate acquired skills. This approach enables each participant to progress at his or her own pace, while meeting the training objectives.  <\/p>\n<h1>6. Detailed program for each day of training<\/h1>\n<h2>Day 1 &#8211; Active Directory fundamentals<\/h2>\n<p><strong>Objective<\/strong>: Lay a solid foundation for understanding AD architecture and components.<\/p>\n<p><strong>Modules<\/strong>:<\/p>\n<ul>\n<li>Overview of the course and concepts covered<\/li>\n<li>Introduction to Active Directory\n<ul>\n<li>History &#038; role in an IS<\/li>\n<li>LDAP, Kerberos, integrated DNS<\/li>\n<\/ul>\n<\/li>\n<li>Logical &#038; physical structure\n<ul>\n<li>Forests, estates, trees<\/li>\n<li>UO, objects, attributes<\/li>\n<li>Sites &#038; domain controllers<\/li>\n<\/ul>\n<\/li>\n<li>Authentication process (interactive vs. network)\n<ul>\n<li>NTLM v1\/v2: operation &#038; limitations<\/li>\n<li>Kerberos: principle, TGT &#038; TGS tickets<\/li>\n<li>Single Sign-On (SSO), delegation, double hop<\/li>\n<li>Domain authentication sequence (with simplified diagram)<\/li>\n<li>Azure AD case study: modern auth (OAuth2, OpenID Connect)<\/li>\n<\/ul>\n<\/li>\n<li>Accounts, groups, GPOs\n<ul>\n<li>Account types<\/li>\n<li>Groups (AGDLP)<\/li>\n<li>GPO concepts: operation and scope<\/li>\n<\/ul>\n<\/li>\n<li>Management tools\n<ul>\n<li>RSAT<\/li>\n<li>PowerShell AD module<\/li>\n<li>Third-party tools (ADExplorer, etc.)<\/li>\n<\/ul>\n<\/li>\n<li>Azure AD and hybrid architectures\n<ul>\n<li>Azure AD vs AD DS: feature comparison<\/li>\n<li>Objects in Azure AD (users, groups, devices)<\/li>\n<li>Connecting two worlds with Azure AD Connect<\/li>\n<li>Usage scenarios: authent cloud, SaaS, Conditional Access<\/li>\n<li>Demo: Azure AD console \/ overview of synchronized identities<\/li>\n<\/ul>\n<\/li>\n<li>Simple PowerShell demos (e.g. Get-ADUser, Get-ADComputer) to anchor databases.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>Day 2 &#8211; AD security (Best practices &#038; hardening)<\/h2>\n<p><strong>Objective<\/strong>: Adopt secure administration practices.<\/p>\n<p><strong>Modules<\/strong>:<\/p>\n<ul>\n<li>Hardening principles\n<ul>\n<li>Principle of least privilege<\/li>\n<li>Tiering (Tier 0\/1\/2)<\/li>\n<li>PAW (Privileged Access Workstation)<\/li>\n<li>DPAPI &#038; Windows LAPS<\/li>\n<\/ul>\n<\/li>\n<li>High-privilege accounts\n<ul>\n<li>Separation of admin \/ user accounts<\/li>\n<li>Supervision of DA accounts<\/li>\n<li>Sensitive groups<\/li>\n<\/ul>\n<\/li>\n<li>GPO and security\n<ul>\n<li>GPO security best practices<\/li>\n<li>Disable SMBv1, macros, etc.<\/li>\n<li>Log configuration<\/li>\n<li>Group Policy Loopback Processing, often misunderstood but useful in Tiering<\/li>\n<\/ul>\n<\/li>\n<li>Access control\n<ul>\n<li>ACLs on AD objects<\/li>\n<li>Authentication: Kerberos vs NTLM<\/li>\n<li>Smartcards, MFA, etc.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>Day 3 &#8211; Common attacks on AD<\/h2>\n<p><strong>Objective <\/strong>: Understand how attacks work to better defend against them.<\/p>\n<p><strong>Modules<\/strong>:<\/p>\n<ul>\n<li>Recognition\n<ul>\n<li>Users &#038; Groups<\/li>\n<li>LDAP, Kerberos &#038; DNS enumeration<\/li>\n<li>GPOs &#038; ACLs<\/li>\n<li>Advanced recognition (ADCS, Relaying &#038; Coercions)<\/li>\n<\/ul>\n<\/li>\n<li>Lateral movements &#038; elevation\n<ul>\n<li>Pass-the-Hash \/ Pass-the-Ticket<\/li>\n<li>Overpass-the-Hash<\/li>\n<li>DCSync \/ DCShadow<\/li>\n<li>Skeleton Key<\/li>\n<li>RBCD &#038; Shadow Credentials<\/li>\n<\/ul>\n<\/li>\n<li>Persistence &#038; exfiltration\n<ul>\n<li>Golden \/ Silver Ticket<\/li>\n<li>Backdoors on ACLs \/ GPOs<\/li>\n<li>Secret extraction via LSASS<\/li>\n<li>SIDHistory injection<\/li>\n<li>Persistence PKI \/ ADCS<\/li>\n<li>Domain trust exploitation<\/li>\n<\/ul>\n<\/li>\n<li>Attack tools\n<ul>\n<li>Mimikatz, Rubeus, BloodHound, CrackMapExec<\/li>\n<li>ADRecon, PowerView, PyKerberoast, PowerSploit<\/li>\n<li>Certipy, PingCastle, SharpHound, Impacket, gpozaurr<\/li>\n<li>Invoke-Kerberoast, dnstool.py, PetitPotam, SpoolSample<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>Day 4 &#8211; Active defense \/ detection<\/h2>\n<p><strong>Objective<\/strong>: Implement a solid, effective defense strategy.<\/p>\n<p><strong>Modules<\/strong>:<\/p>\n<ul>\n<li>Audit &#038; logging\n<ul>\n<li>Advanced security auditing (e.g. GPO changes, DA members)<\/li>\n<li>Sysmon + Event Forwarding<\/li>\n<li>GPO audit &#038; authentication<\/li>\n<\/ul>\n<\/li>\n<li>Detection &#038; monitoring\n<ul>\n<li>ATA \/ Defender for Identity<\/li>\n<li>SIEM (e.g. Splunk, ELK, Sentinel)<\/li>\n<li>Honeytokens &#038; lures<\/li>\n<\/ul>\n<\/li>\n<li>AD incident response\n<ul>\n<li>What to do after a compromised DC<\/li>\n<li>Post-operation playbook for AAL<\/li>\n<li>Post-operation playbook for On-prem AD<\/li>\n<li>AD-specific response tools<\/li>\n<\/ul>\n<\/li>\n<li>Final hardening &#038; testing\n<ul>\n<li>CIS \/ Microsoft benchmarks<\/li>\n<li>AD Baseline Analyzer<\/li>\n<li>Exposure testing tools (PingCastle, GPOAnalyzer, MSSecBaseline etc.)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Registration: Contact us at <a href=\"https:\/\/www.hackmosphere.fr\/en\/contact\/\">https:\/\/www.hackmosphere.fr\/contact<\/a> <\/strong><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Training Program: Pentest Active Directory Trainer: Florian Ecard &#8211; Ethical hacker &#8211; fecard@hackmosphere.fr &#8211; 06.49.98.89.87 Target audience: System\/network administrators, SOC teams, CISOs, junior pentesters 1. Pedagogical objectives Understand the legal and methodological framework of a security audit. Master the technical fundamentals of Pentest. Understand the architecture and risks associated with Active Directory (AD) and Entra [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_seopress_titles_title":"Ethical hacking training program: Active Directory & Entra ID","_seopress_titles_desc":"In this course, learners will understand the architecture of Active Directory (AD) and Entra ID, and how to identify, exploit and remediate vulnerabilities.","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"both","_seopress_redirections_param":"","_seopress_redirections_type":301,"_seopress_analysis_target_kw":"","_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"class_list":["post-3959","page","type-page","status-publish"],"_links":{"self":[{"href":"https:\/\/www.hackmosphere.fr\/en\/wp-json\/wp\/v2\/pages\/3959","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hackmosphere.fr\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.hackmosphere.fr\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.hackmosphere.fr\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hackmosphere.fr\/en\/wp-json\/wp\/v2\/comments?post=3959"}],"version-history":[{"count":24,"href":"https:\/\/www.hackmosphere.fr\/en\/wp-json\/wp\/v2\/pages\/3959\/revisions"}],"predecessor-version":[{"id":4903,"href":"https:\/\/www.hackmosphere.fr\/en\/wp-json\/wp\/v2\/pages\/3959\/revisions\/4903"}],"wp:attachment":[{"href":"https:\/\/www.hackmosphere.fr\/en\/wp-json\/wp\/v2\/media?parent=3959"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}